2026 CVE Vulnerabilities
64,616 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42728 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Cont... |
| CVE-2026-42727 | CRITICAL | 9.3 | 0.3% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active ... |
| CVE-2026-42726 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Explo... |
| CVE-2026-42725 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout... |
| CVE-2026-3349 | MEDIUM | 6.1 | 0.3% | May 27, 2026 | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter o... |
| CVE-2026-3348 | MEDIUM | 4.4 | 0.2% | May 27, 2026 | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (D... |
| CVE-2026-3012 | MEDIUM | 6.8 | 0.3% | May 27, 2026 | A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabl... |
| CVE-2026-2288 | MEDIUM | 4.8 | 0.2% | May 27, 2026 | The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all ... |
| CVE-2026-2280 | MEDIUM | 4.8 | 0.2% | May 27, 2026 | The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t... |
| CVE-2026-8054 | CRITICAL | 10 | 1.6% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints ... |
| CVE-2026-49002 | CRITICAL | 9.1 | 0.3% | May 27, 2026 | Access control failure means that an application does not effectively check user access permissions, so that unauthorize... |
| CVE-2026-48968 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slid... |
| CVE-2026-48877 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive... |
| CVE-2026-40852 | HIGH | 7.2 | 0.4% | May 27, 2026 | A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. T... |
| CVE-2026-40851 | HIGH | 8.4 | 0.1% | May 27, 2026 | A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to... |
| CVE-2026-40850 | HIGH | 8.7 | 0.4% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData func... |
| CVE-2026-40849 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile vi... |
| CVE-2026-40848 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to impr... |
| CVE-2026-40847 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due ... |
| CVE-2026-40846 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to i... |
| CVE-2026-40845 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuratio... |
| CVE-2026-40844 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due t... |
| CVE-2026-40843 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to... |
| CVE-2026-40842 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags functi... |
| CVE-2026-40841 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags funct... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now